GEO my WP
- <= 4.5.4
A SQL injection vulnerability has been identified in the GEO My WP plugin for WordPress, affecting versions through 4.5.4. The issue arises in the proximity search feature, where the 'distance', 'lat', and 'lng' parameters are improperly sanitized. The vulnerability allows attackers to inject malicious SQL payloads that could be executed by the database, potentially leading to unauthorized data access or manipulation.
Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the WordPress site.
To reproduce this vulnerability, send a request to a WordPress site with the GEO My WP plugin installed, using the 'distance', 'lat', or 'lng' parameters. The injected SQL payloads can be crafted to exploit the SQL injection vulnerability by, for example, using '1 OR SLEEP(3)' to test for SQL injection availability.
Users are advised to update the GEO My WP plugin to version 4.5.5 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.